CVE-2026-9692: Hayajo Mojolicious::sessions::storable
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, the heap address of an anonymous hash, and the PID. These are predictable or low-entropy sources that are unsuitable for security purposes.
Affected products
- Hayajo Mojolicious::sessions::storable: up to and including 0.05
Published 2026-06-18. Last modified 2026-06-22.